Integer Underflow Vulnerability in STMicroelectronics X-CUBE-AZRTOS-WL HTTP Server
CVE-2024-50596

4.3MEDIUM

What is CVE-2024-50596?

An integer underflow vulnerability in the HTTP server implementation of STMicroelectronics X-CUBE-AZRTOS-WL version 2.0.0 poses a risk of denial of service. By sending a specially crafted network packet, an attacker can exploit this vulnerability to disrupt the service. The issue is rooted in the NetX Duo Web Component, particularly in the functionality handling HTTP PUT requests, which can be found in the source code file nx_web_http_server.c. This flaw allows for potential service interruptions, highlighting the need for secure coding practices and timely updates to mitigate such risks.

Affected Version(s)

X-CUBE-AZRT-H7RS 1.0.0

X-CUBE-AZRTOS-F4 1.1.0

X-CUBE-AZRTOS-F7 1.1.0

References

CVSS V3.1

Score:
4.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Discovered by Kelly Patterson of Cisco Talos.
.